Executive brief
Sendmail, a widely used mail transfer agent for routing and delivering email, contains a critical security flaw. An unauthenticated remote attacker can exploit this vulnerability to execute commands with administrative (root) privileges. This could lead to a complete takeover of the mail server, allowing unauthorized access to all emails and the ability to disrupt communications or launch further attacks on the network.
Technical details
A remote code execution vulnerability exists in Sendmail 8.6.9 due to improper handling of responses from the Identification Protocol (ident). By providing a specially crafted ident response during a connection, a remote, unauthenticated attacker can trigger a buffer overflow or similar memory corruption to execute arbitrary commands with root privileges. This attack is performed over the network without requiring user interaction. Organizations should upgrade to a patched version of Sendmail or disable ident lookups if they are not required for operations.
Affected products
- Sendmail Sendmail 8.6.9
Timeline
- 1997-01-01: disclosed: Initial publication date recorded in NVD.